|
|
|
|
Strumenti |
27-05-2009, 18:03 | #81 | |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
Quote:
Apri il debugger e dove ti dice di inserire il percorso dei symbols inserisci una stringa che era stata suggerita e che ti faceva scaricare i symbols giusti direttamente da MS. Cerca tra i posts e la trovi. |
|
28-05-2009, 14:39 | #82 |
Senior Member
Iscritto dal: Nov 2008
Città: Verona
Messaggi: 776
|
Ecco il debug. Chi mi sa aiutare?
Codice:
******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 3B, {c0000005, fffff800020d7a36, fffffa6007d5e2b0, 0} Probably caused by : ntkrnlmp.exe ( nt!NtClearEvent+37 ) Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner --------- 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: fffff800020d7a36, Address of the exception record for the exception that caused the bugcheck Arg3: fffffa6007d5e2b0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s. FAULTING_IP: nt!ObReferenceObjectByHandle+206 fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] CONTEXT: fffffa6007d5e2b0 -- (.cxr 0xfffffa6007d5e2b0) rax=0000000000000001 rbx=fffffa6007d5ec28 rcx=00000000000002f4 rdx=0000000000000002 rsi=0000000000715500 rdi=fffffa800423a060 rip=fffff800020d7a36 rsp=fffffa6007d5eb10 rbp=0000000000000000 r8=fffff880106a7000 r9=0000100000000000 r10=fffff800020d0e00 r11=000000000026f100 r12=fffff8800d411110 r13=00000000000002f4 r14=0000000000000001 r15=fffffa800512b830 iopl=0 nv up ei pl nz na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206 nt!ObReferenceObjectByHandle+0x206: fffff800`020d7a36 4b8b0408 mov rax,qword ptr [r8+r9] ds:002b:00000880`106a7000=???????????????? Resetting default scope CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x3B PROCESS_NAME: CoDWaW.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff800020d0e37 to fffff800020d7a36 STACK_TEXT: fffffa60`07d5eb10 fffff800`020d0e37 : 00000000`000bfa00 fffff800`00000002 fffffa80`039aedc0 00000000`00000001 : nt!ObReferenceObjectByHandle+0x206 fffffa60`07d5ebe0 fffff800`01e5ddf3 : fffffa80`0423a060 00000000`00000000 00000000`00da7a64 fffffa80`047000f0 : nt!NtClearEvent+0x37 fffffa60`07d5ec20 00000000`75c23d09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 00000000`0007ee68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x75c23d09 FOLLOWUP_IP: nt!NtClearEvent+37 fffff800`020d0e37 85c0 test eax,eax SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!NtClearEvent+37 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 48d1ba35 STACK_COMMAND: .cxr 0xfffffa6007d5e2b0 ; kb FAILURE_BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 BUCKET_ID: X64_0x3B_nt!NtClearEvent+37 Followup: MachineOwner ---------
__________________
CASE: Cooler Master CM690; POWER SUPPLY: Corsair TX650W; MOTHERBOARD: Asus P5Q Pro; CPU: Core 2 Quad Q6600 @ 3.0Ghz + AC Freezer 7 PRO; VGA: Sapphire HD 7850 1GB OC; HD: Seagate Barracuda 500GB; RAM: Corsair DDR2 800Mhz 2X2GB MONITOR: Samsung T200 |
28-05-2009, 20:22 | #83 |
Senior Member
Iscritto dal: Jan 2005
Messaggi: 21550
|
A me su 7 con la 1900xt e i driver che scarica win update ha dato due volte schermata blu quando applicavo un'immagine come sfondo, credo sia dovuto ai driver acerbi...l'ha fatto a qualcun altro?
__________________
cpu amd ryzen 7600 | mobo msi b650 tomahawk | ram g.skill trident z5 neo 2x16gb | ssd wd sn850x 2tb | vga asus 4070 super | ali msi a850g | case cm qube 500 | monitor lg 27gr75q | keyboard yunzii al71 |
28-05-2009, 20:39 | #84 | |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
Quote:
perchè compare la voce "PROCESS_NAME: CoDWaW.exe". |
|
28-05-2009, 21:52 | #85 |
Senior Member
Iscritto dal: Nov 2008
Città: Verona
Messaggi: 776
|
Esatto, ma la voce da guardare è questa:
IMAGE_NAME: ntkrnlmp.exe E' un file di Windows, ma non ho trovato molte informazioni a riguardo.
__________________
CASE: Cooler Master CM690; POWER SUPPLY: Corsair TX650W; MOTHERBOARD: Asus P5Q Pro; CPU: Core 2 Quad Q6600 @ 3.0Ghz + AC Freezer 7 PRO; VGA: Sapphire HD 7850 1GB OC; HD: Seagate Barracuda 500GB; RAM: Corsair DDR2 800Mhz 2X2GB MONITOR: Samsung T200 |
28-05-2009, 22:03 | #86 |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
|
28-05-2009, 22:05 | #87 |
Senior Member
Iscritto dal: Nov 2008
Città: Verona
Messaggi: 776
|
Ho il processore a 3Ghz anzichè 2.4. Ma non penso sia l'OC la causa, per me è proprio Winzozz
__________________
CASE: Cooler Master CM690; POWER SUPPLY: Corsair TX650W; MOTHERBOARD: Asus P5Q Pro; CPU: Core 2 Quad Q6600 @ 3.0Ghz + AC Freezer 7 PRO; VGA: Sapphire HD 7850 1GB OC; HD: Seagate Barracuda 500GB; RAM: Corsair DDR2 800Mhz 2X2GB MONITOR: Samsung T200 |
28-05-2009, 22:10 | #88 |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
Io avevo questo problema perchè le ram non erano settate bene pur stanto su auto. Strano vero? Comunque io vedrei le ram come le hai settate. Di solito questi problemi sono provocati da un settaggio sbagliato delle ram per OC oppure da qualche errore delle stesse. Hai provato a fare un test con Memtest?
Io cercherei sul forum dei suggerimenti per settare correttamente il bios per tenere la CPU a 3.0Ghz. Quando avevo il E8500 e lo tenevo a 4.1 Ghz avevo dovuto settare varie voci del bios per non avere crash di questo tipo comprese le ram e il voltaggio. |
29-05-2009, 00:09 | #89 |
Senior Member
Iscritto dal: May 2003
Città: Napoli (Arenella) Trattative a buon fine:71
Messaggi: 4294
|
ma il mio log nessuno l'ha visto crycry e' 3 post su
__________________
Mela: Macbook Air i5 2020. PC: Thermaltake P3+Z170-A+Intel i7 6700k@4,5Ghz+NZXT KrakenX62+Corsair Vengeance C16@3,2ghz+Samsung 840EVO250Gb+Samsung 970 EVO Plus NVMe M.2+Gygabyte Gtx 1080 G1. Asus MX27UQ. Fidelio X1@Schiit Modi+Magni Nikon D7000+Sigma 17-70mm f/2.8-4 DC Macro OS HSM+ 105mm f2.8 EX DG macro Nikkor 50mm AF-S 1.8G flickr™ |
29-05-2009, 00:41 | #90 |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
|
29-05-2009, 01:02 | #91 | |
Senior Member
Iscritto dal: May 2003
Città: Napoli (Arenella) Trattative a buon fine:71
Messaggi: 4294
|
Quote:
Ho fatto scandisk con ripristino di settori (insomma la seconda opzione dello scandisk) durato 2 ore ma niente...
__________________
Mela: Macbook Air i5 2020. PC: Thermaltake P3+Z170-A+Intel i7 6700k@4,5Ghz+NZXT KrakenX62+Corsair Vengeance C16@3,2ghz+Samsung 840EVO250Gb+Samsung 970 EVO Plus NVMe M.2+Gygabyte Gtx 1080 G1. Asus MX27UQ. Fidelio X1@Schiit Modi+Magni Nikon D7000+Sigma 17-70mm f/2.8-4 DC Macro OS HSM+ 105mm f2.8 EX DG macro Nikkor 50mm AF-S 1.8G flickr™ |
|
29-05-2009, 01:12 | #92 |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
|
29-05-2009, 01:57 | #93 |
Senior Member
Iscritto dal: May 2003
Città: Napoli (Arenella) Trattative a buon fine:71
Messaggi: 4294
|
FUJITSU MHY2200BH ATA Device
__________________
Mela: Macbook Air i5 2020. PC: Thermaltake P3+Z170-A+Intel i7 6700k@4,5Ghz+NZXT KrakenX62+Corsair Vengeance C16@3,2ghz+Samsung 840EVO250Gb+Samsung 970 EVO Plus NVMe M.2+Gygabyte Gtx 1080 G1. Asus MX27UQ. Fidelio X1@Schiit Modi+Magni Nikon D7000+Sigma 17-70mm f/2.8-4 DC Macro OS HSM+ 105mm f2.8 EX DG macro Nikkor 50mm AF-S 1.8G flickr™ |
29-05-2009, 14:20 | #94 |
Senior Member
Iscritto dal: Jan 2005
Messaggi: 21550
|
Al momento di caricare il file dmp con windows debugger, mi dice che non ho le autorizzazioni necessarie, eppure sono loggato come amministratore...come posso risolvere?
__________________
cpu amd ryzen 7600 | mobo msi b650 tomahawk | ram g.skill trident z5 neo 2x16gb | ssd wd sn850x 2tb | vga asus 4070 super | ali msi a850g | case cm qube 500 | monitor lg 27gr75q | keyboard yunzii al71 |
29-05-2009, 15:09 | #95 | |
Senior Member
Iscritto dal: Nov 2008
Città: Verona
Messaggi: 776
|
Quote:
Com MEmtest cosa si pu vedere? Perchè so che dura tantissimo, mi tocca lasciare il pc acceso tutta la notte.
__________________
CASE: Cooler Master CM690; POWER SUPPLY: Corsair TX650W; MOTHERBOARD: Asus P5Q Pro; CPU: Core 2 Quad Q6600 @ 3.0Ghz + AC Freezer 7 PRO; VGA: Sapphire HD 7850 1GB OC; HD: Seagate Barracuda 500GB; RAM: Corsair DDR2 800Mhz 2X2GB MONITOR: Samsung T200 |
|
30-05-2009, 15:57 | #96 |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
Con memtest, versione bootabile testi le ram magari 1 banco per volta e vedi se hanno problemi e se danno errori significa che hanno problemi che poi si ripercuotono sul S.O.
|
30-05-2009, 18:56 | #97 | ||
Senior Member
Iscritto dal: Apr 2001
Città: Giovinazzo(BA) ...bella città, riso patat e cozz a volontà!
Messaggi: 26487
|
Quote:
Quote:
Secondariamente, proverei in successione quanto segue: - disattiva il Cool and Quite se hai una cpu AMD o C1e e SpeedStep in caso di cpu Intel. Volendo, potresti provare a lasciarli attivi da bios disattivando il risparmio energetico del processore in Windows Vista; - assicurati di aver aggiornato i driver della scheda video; - imposta, per il processo di CoD5, l'affinità per un singolo core del processore: Vista/Win7 - Affinità processori multicore Altrimenti va eseguito un controllo hardware delle memorie, ad esempio con Memtest come suggeriva Crimsom. In questo thread trovi link per il download e relative guide all'utilizzo dei software citati: Analisi e comparativa tool/procedure di emergenza Avvia il debugger come amministratore (tasto destro --> Esegui come amministratore), altrimenti Windbg non potrà accedere a c:\Windows
__________________
Ezio Lacandia on DeviantArt | Slimkat mod per N4 e N5 | Trattative mercatino HWU | Driver nForce NET Framework [Guida] | BSOD individuazione cause | Guida Sintetica Strap/Divisori P45 | Fix associazioni Vista/7 Problemi Win Installer | Avviare programmi senza richiesta UAC | Problemi Font | Guida Raccolte 7 | Win 32/64bit come perchè |
||
30-05-2009, 20:30 | #98 |
Bannato
Iscritto dal: Feb 2008
Città: Roma
Messaggi: 2453
|
Condordo. Il solo O.C. della CPU deve essere accompagnato dalle altre variabili del bios come già avevo suggerito. Togli l'O.C. e vedi se da ancora problemi.
|
30-05-2009, 22:55 | #99 | |
Senior Member
Iscritto dal: May 2003
Città: Napoli (Arenella) Trattative a buon fine:71
Messaggi: 4294
|
Quote:
Ma in questo caso che posso fare??
__________________
Mela: Macbook Air i5 2020. PC: Thermaltake P3+Z170-A+Intel i7 6700k@4,5Ghz+NZXT KrakenX62+Corsair Vengeance C16@3,2ghz+Samsung 840EVO250Gb+Samsung 970 EVO Plus NVMe M.2+Gygabyte Gtx 1080 G1. Asus MX27UQ. Fidelio X1@Schiit Modi+Magni Nikon D7000+Sigma 17-70mm f/2.8-4 DC Macro OS HSM+ 105mm f2.8 EX DG macro Nikkor 50mm AF-S 1.8G flickr™ |
|
31-05-2009, 11:42 | #100 | |
Senior Member
Iscritto dal: Nov 2008
Città: Verona
Messaggi: 776
|
Quote:
-Driver aggiornati, Catalyst 9.5 appena usciti. -Lo farò, e verificherò se la schermata si ripete solo con CoD5 o anche con altri igochi. Ricordo però che mi apparse una schermata blu anche giocando a GTAIV, ma non ho avuto l'occasione di analizzare il log. Prossimamente farò anche il Memtest, intanto grazie a tutti per l'aiuto.
__________________
CASE: Cooler Master CM690; POWER SUPPLY: Corsair TX650W; MOTHERBOARD: Asus P5Q Pro; CPU: Core 2 Quad Q6600 @ 3.0Ghz + AC Freezer 7 PRO; VGA: Sapphire HD 7850 1GB OC; HD: Seagate Barracuda 500GB; RAM: Corsair DDR2 800Mhz 2X2GB MONITOR: Samsung T200 |
|
Strumenti | |
|
|
Tutti gli orari sono GMT +1. Ora sono le: 01:04.